First published: Fri Feb 07 2025(Updated: )
Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.
Credit: security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet | <7.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27017 has been categorized as a medium severity vulnerability.
To fix CVE-2021-27017, upgrade to Puppet Agent version 7.4.0 or later.
CVE-2021-27017 allows the deserialization of untrusted data, which can lead to security risks.
Puppet Agent versions prior to 7.4.0 are affected by CVE-2021-27017.
Yes, CVE-2021-27017 is exploitable if untrusted data is deserialized in the Puppet Agent.